Last updated 6 September 2026
ASA Condor manages Apple Search Ads campaigns on your behalf. To do that it has to hold a narrow set of things about you and your apps. This page says exactly which, why, and who else sees them. It describes what the product actually does today, not what it might do.
ASA Condor is operated by Manuel Couto (Portugal). For questions about your data, or to exercise any of the rights below, write to coutocf@gmail.com.
| Data | Why | Basis |
|---|---|---|
| Your email address and Apple sign-in identifier | To sign you in and to keep your account separate from everyone else's. | Performing our contract with you |
| An access token for your Apple Ads account | To read your campaigns and make the changes you approve. Stored encrypted; we never see or hold your Apple ID password. | Performing our contract with you |
| Your campaign, keyword and search-term performance | This is the raw material of the analysis. It comes from Apple, not from your users. | Performing our contract with you |
| A RevenueCat API key, if you choose to connect one | To read aggregate revenue for your app and work out what an install is worth to you. Stored encrypted. Optional — the product works without it. | Your consent, withdrawable at any time by removing the connection |
| A record of every change the agent makes | So you can see what was done to your account and what it cost or saved. | Performing our contract with you |
| An email address you enter on the waiting list | To tell you when the product opens. Nothing else. | Your consent |
What is not held. ASA Condor never receives data about your app's users. It reads aggregate figures from Apple and RevenueCat — installs, spend, revenue totals — and nothing that identifies an individual person who installed your app. It also never receives your Apple ID password: the connection is made through Apple's own sign-in, and can be revoked from your Apple account at any time.
These are the only third parties involved, and each sees only what its job requires:
| Service | What it sees | Where |
|---|---|---|
| Clerk | Your email address and sign-in identity | United States |
| Apple (Search Ads API) | Your campaigns, and the changes you approve | United States |
| Google (Gemini API) | Your app's public App Store name, category and description, when generating keyword ideas. No account or revenue data is sent. | United States |
| RevenueCat | Only if you connect it, and only aggregate revenue is read back | United States |
| Hetzner | Hosts the server your data sits on | Germany |
| Cloudflare | Serves this website and stores waiting-list emails | Global network |
Transfers outside the EU rely on the European Commission's Standard Contractual Clauses, which these providers offer as part of their terms.
Under the GDPR you can ask for a copy of your data, ask for it to be corrected or deleted, object to how it is used, or ask for it in a portable form. Write to coutocf@gmail.com and you will get an answer within 30 days. You can also complain to your national data protection authority; in Portugal that is the CNPD.
Credentials — your Apple access token and any RevenueCat key — are encrypted at rest with AES-256-GCM, using a key held separately from the data itself. Traffic runs over HTTPS. Backups are taken daily and are subject to the same retention as above.
This is a small operation, honestly described: it is one developer, one server, and the measures above. It is not an enterprise security programme, and this page will be updated rather than quietly outgrown if that changes.
This website sets no analytics or advertising cookies. The application sets what Clerk needs to keep you signed in, and nothing else.
If this policy changes in a way that affects you, you will be told by email before it takes effect. The date at the top always reflects the current version.